CVE detail
CVE-2018-11426 — CVE-2018-11426
Published 2019-07-03 · Modified 2026-06-17 · Vendor moxa · Product oncell_g3150-hspa_firmware · Source nvd
CRITICAL
severity
CVSS-derived band
0.0184
EPSS probability
exploitation probability, 30d
77.0%
EPSS percentile
percentile vs all CVEs
NOT LISTED
CISA KEV
known exploited catalog
Description
A weak Cookie parameter is used in the web application of Moxa OnCell G3100-HSPA Series version 1.4 Build 16062919 and prior. An attacker can brute force parameters required to bypass authentication and access the web interface to use all its functions except for password change.
Remediation
No vendor-published fix data in our corpus for this CVE. Check the references below or the vendor's PSIRT / security advisories page.
References